CVE Feed

    Dashboard / CVE / CVE-2026-34473

    CVE-2026-34473

    Unauthenticated DoS in ZTE H8102E, H168N, H167A, H199A, H288A, H198A, H267A, H267N, H268A, H388X, H196A, H369A, H268N, H208N, H367N, H181A, and H196Q. A denial-of-service condition can be triggered against the router's web interface by sending an oversized application/x-www-form-urlencoded POST body. After triggering, the management interface may become unresponsive until the device is rebooted. This may affect any firmware version prior to 2022 (reporter observation). The supplier stated that devices are not vulnerable since 2021-03-23; operator firmware may vary.

    Published:May 6, 2026
    Last Modified:May 30, 2026
    EPS:May 6, 2026
    EPSS Score:0.01634
    CVSS Score:7.5

    Affected Products

    Vendor
    Zte
    Product
    H167A
    Vendor
    Zte
    Product
    H168N
    Vendor
    Zte
    Product
    H181A
    Vendor
    Zte
    Product
    H196A
    Vendor
    Zte
    Product
    H196Q
    Vendor
    Zte
    Product
    H198A
    Vendor
    Zte
    Product
    H199A
    Vendor
    Zte
    Product
    H208N
    Vendor
    Zte
    Product
    H267A
    Vendor
    Zte
    Product
    H267N
    Vendor
    Zte
    Product
    H268A
    Vendor
    Zte
    Product
    H268N
    Vendor
    Zte
    Product
    H288A
    Vendor
    Zte
    Product
    H367N
    Vendor
    Zte
    Product
    H369A
    Vendor
    Zte
    Product
    H388X
    Vendor
    Zte
    Product
    H8102E

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High